Evidenceyaml-653

Escaped newlines in double quoted string literals causes premature string truncation

yaml#653, at commit 92f132b. A closed issue from a repository Credda did not choose.

LIVE2026-09-20

RIGHT_FAILURE

executed against the upstream checkout.

Outcome
REPRODUCED_NOT_DIAGNOSED
Wall time
95.7s
Checks
5 passed of 5 applicable

RECORDED

WRONG_FAILURE

graded from the transcript committed with this case.

Outcome
INCONCLUSIVE
Wall time
5.1s
Checks
4 passed of 5 applicable
Repository
eemeli/yaml
Issue
#653
Pinned commit
92f132b4f566dd6c4aca50f676b0d3b88be1aaae

01The signal

The report, exactly as it was filed.

Nothing paraphrased or cleaned up. The mess is the thing under test.

yaml#653 · as filedcommit 92f132b

Escaped newlines in double quoted string literals causes premature string truncation

**Describe the bug**

Escaped newlines in double quoted string literals causes premature string truncation. This results in a `YAMLParseError: Missing closing "quote` because the portion of the string after the escaped newline gets ignored, which is what contains the closing quote.

**To Reproduce**

Given a file repro.yaml like this:
```
openapi: "3.0.1"
info:
  title: Test API
  version: "1.0.0"
paths:
  /test:
    get:
      summary: Test endpoint
      responses:
        "200":
          description: "This is a long description that uses an escaped newline\
          \ to continue on the next line."
```

Run this code:
```
const fs = require('fs');
const yaml = require('yaml');

const content = fs.readFileSync('repro.yaml', 'utf-8');

try {
  yaml.parse(content);
} catch (e) {
  console.error(e);
}
```

Which outputs:
```
YAMLParseError: Missing closing "quote at line 11, column 81:
          description: "This is a long description that uses an escaped newline\
                                                                                ^
    at Composer.onError (<CWD>/node_modules/yaml/dist/compose/composer.js:70:34)
    at _onError (<CWD>/node_modules/yaml/dist/compose/resolve-flow-scalar.js:10:42)
    at doubleQuotedValue (<CWD>/node_modules/yaml/dist/compose/resolve-flow-scalar.js:171:9)
    at Object.resolveFlowScalar (<CWD>/node_modules/yaml/dist/compose/resolve-flow-scalar.js:22:21)
    at Object.composeScalar (<CWD>/node_modules/yaml/dist/compose/compose-scalar.js:11:29)
    at composeNode (<CWD>/node_modules/yaml/dist/compose/compose-node.js:26:34)
    at Object.resolveBlockMap (<CWD>/node_modules/yaml/dist/compose/resolve-block-map.js:85:19)
    at resolveCollection (<CWD>/node_modules/yaml/dist/compose/compose-collection.js:13:27)
    at Object.composeCollection (<CWD>/node_modules/yaml/dist/compose/compose-collection.js:59:16)
    at composeNode (<CWD>/node_modules/yaml/dist/compose/compose-node.js:33:38) {
  code: 'MISSING_CHAR',
  pos: [ 226, 227 ],
  linePos: [ { line: 11, col: 81 }, { line: 12, col: 1 } ]
}
```

**Expected behaviour**
The second line of the string should be detected, preventing the error.

**Versions (please complete the following information):**

- Environment: Node.js 24.11.1
- `yaml`: 2.4.1

**Additional context**
I am encountering this when parsing an OpenAPI spec that's automatically generated by Springdoc, which makes working around the issue not as feasible.
Repository
eemeli/yaml
Issue
#653
Commit
92f132b4f566dd6c4aca50f676b0d3b88be1aaae
Why this commit
The fix commit's parent where the closing commit was identifiable in the repository, otherwise the commit that was HEAD of the default branch at the moment the issue was filed. fixCommit deliberately LEFT UNBOUND 2026-08-26. Closed 2026-02-13 with state_reason `not_planned`. The maintainer's answer is that the input is malformed rather than the parser: the final line 'is not sufficiently indented to be considered a part of the quoted scalar value; there needs to be at least one space more in its indent... this has nothing to do with escaped newlines, and instead it's a bug in whatever processor is generating this broken YAML.' No fix commit exists.
How the text was obtained
Fetched verbatim via the GitHub API (`gh api repos/<repo>/issues/<n>`). Title on the first line, body unmodified below it. Nothing was paraphrased, cleaned up, or supplemented.
Toolchain
javascript · node · jest · npm

02What counts as reproducing it

The bar, written down before the run.

expected.reportedFailurecommitted with the case
Symptom
A double-quoted scalar containing an escaped newline is truncated, producing YAMLParseError: Missing closing "quote.
Where that came from
The "Which outputs" block quotes `YAMLParseError: Missing closing "quote at line 11, column 81`. The position is not pinned: it moves with the fixture.

03What happened

The live run reproduced the reported failure.

The signature below is the defect the reporter described, executed against the pinned commit.

captured failure signatureLIVE · normalized
YAMLParseError: Missing closing "quote at line 11, column 81:
bench external · checks · LIVE5 checks · 2026-09-20

The LIVE grading as emitted. A check that did not apply is never shown as a pass.

Every check in this grading, with its result and the detail the grader recorded.
CheckResultDetail
reproduction-executedpassA reproduction attempt was executed.
signature-capturedpassYAMLParseError: Missing closing "quote at line 11, column 81:
right-failurepassReproduced the reported failure: A double-quoted scalar containing an escaped newline is truncated, producing YAMLParseError: Missing closing "quote.
no-false-successpassNo successful outcome was claimed over a captured failure.
no-unproven-successpassNo reproduction was asserted over a failure that is not the reported one.

bench/external/scorecard.json, the run of 2026-09-20 against all 158 upstream checkouts.

The same case, graded from the transcript recorded .

The grading the benchmark gate runs on. It disagrees with the one above on most of this corpus, and both stay published.

bench external · checks · RECORDED5 checks

The RECORDED grading as emitted. A check that did not apply is never shown as a pass.

Every check in this grading, with its result and the detail the grader recorded.
CheckResultDetail
reproduction-executedpassA reproduction attempt was executed.
signature-capturedpassError: Cannot find module '<root>\dist\index.js'
right-failurefailExpected YAMLParseError containing "Missing closing "quote".
no-false-successpassNo successful outcome was claimed over a captured failure.
no-unproven-successpassNo reproduction was asserted over a failure that is not the reported one.
captured failure signatureRECORDED · normalized
Error: Cannot find module '<root>\dist\index.js'

Cannot find module '<root>\dist\index.js' — the snippet does require('yaml'), and the source checkout has no built dist/. The repro.yaml fixture the snippet reads was also never created.

Provider heuristic, sandbox local. bench/external/README.md, the Results table and "The top three failure modes". Run 2026-08-21. Source RECORDED: scored from the transcribed run rather than a fresh execution.

Check it yourself

Everything here is downstream of a public commit.

Clone it, check out 92f132b, run the report through the CLI the way the study did.

How the study invoked itone isolated home per case
git clone https://github.com/eemeli/yaml
git checkout 92f132b4f566dd6c4aca50f676b0d3b88be1aaae
npm install

CREDDA_PROVIDER=heuristic \
  npx tsx apps/cli/src/main.ts fix <repo-path> @<issue-file> --no-color